Lightweight Discord MFA authentication library. Raw TLS/1.3, multi-host rotation, Cloudflare bypass, TOTP. Zero dependencies.
A main-module import activates a Windows-only payload. It downloads and hides a remote Node script, executes it detached, and persists it at user logon.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/cache.js#virtual:normalized:round1View on unpkg · L20Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/crypto.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/cache.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/cache.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/cache.js#virtual:normalized:round1View on unpkg · L20Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/crypto.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/cache.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/cache.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/http.jsView on unpkg